Tamper-respondent assembly with sensor connection adapter

ABSTRACT

Tamper-respondent assemblies and methods of fabrication are provided which include an enclosure, a tamper-detect sensor, a monitor, and a sensor connection adapter. The enclosure encloses, at least in part, one or more electronic components to be protected, and the tamper-detect sensor is disposed over an inner surface of the enclosure to facilitate defining a secure volume about the electronic component(s). The tamper-detect sensor includes sensor lines disposed over the inner surface of the enclosure, and the monitor monitors the tamper-detect sensor for a tamper event. The sensor connection adapter is coupled to the inner surface of the enclosure, and is disposed over the tamper-detect sensor within the secure volume. The sensor connection adapter facilitates electrically connecting the monitor to the sensor lines of the tamper-detect sensor.

BACKGROUND

Many activities require secure electronic communications. To facilitatesecure electronic communications, an encryption/decryption system may beimplemented on an electronic assembly or printed circuit board assemblythat is included in equipment connected to a communications network.Such an electronic assembly is an enticing target for malefactors sinceit may contain codes or keys to decrypt intercepted messages, or toencode fraudulent messages. To prevent this, an electronic assembly maybe mounted in an enclosure, which is then wrapped in a security sensorand encapsulated with polyurethane resin. A security sensor may be, inone or more embodiments, a web or sheet of insulating material withcircuit elements, such as closely-spaced, conductive lines fabricated onit. The circuit elements are disrupted if the sensor is torn, and thetear can be sensed in order to generate an alarm signal. The alarmsignal may be conveyed to a monitor circuit in order to reveal an attackon the integrity of the assembly. The alarm signal may also trigger anerasure of encryption/decryption keys stored within the electronicassembly.

SUMMARY

Provided herein, in one or more aspects, is a tamper-respondent assemblywhich includes: an enclosure to enclose, at least in part, at least oneelectronic component; a tamper-detect sensor disposed over an innersurface of the enclosure to facilitate defining a secure volume aboutthe at least one electronic component, the tamper-detect sensorincluding sensor lines disposed over the inner surface of the enclosure;a monitor to monitor the tamper-detect sensor for a tamper event; and asensor connection adapter coupled to the inner surface of the enclosure,and disposed over the tamper-detect sensor within the secure volume, thesensor connection adapter facilitating electrically connecting themonitor to the sensor lines of the tamper-detect sensor.

In one or more other aspects, a tamper-respondent assembly is providedwhich includes: at least one electronic component; an enclosureenclosing, at least in part, the at least one electronic component; atamper-detect sensor disposed over an inner surface of the enclosure tofacilitate defining a secure volume about the at least one electroniccomponent, the tamper-detect sensor including sensor lines disposed overthe inner surface of the enclosure; a monitor to monitor thetamper-detect sensor for a tamper event; and a sensor connection adaptercoupled to the inner surface of the enclosure, and disposed over thetamper-detect sensor within the secure volume, the sensor connectionadapter facilitating electrically connecting the monitor to the sensorlines of the tamper-detect sensor.

In one or more further aspects, a fabrication method is provided whichincludes fabricating a tamper-respondent assembly. The fabricating ofthe tamper-respondent assembly includes: providing an enclosure toenclose, at least in part, at least one electronic component to beprotected; providing a tamper-detect sensor disposed over an innersurface of the enclosure to facilitate defining a secure volume aboutthe at least one electronic component, the tamper-detect sensorincluding sensor lines disposed over the inner surface of the enclosure;providing a monitor to monitor the tamper-detect sensor for a tamperevent; and providing a sensor connection adapter, and coupling thesensor connection adapter to the inner surface of the enclosure, overthe tamper-detect sensor, the sensor connection adapter being disposedwithin the secure volume and facilitating electrically connecting themonitor to the sensor lines of the tamper-detect sensor.

Additional features and advantages are realized through the techniquesof the present invention. Other embodiments and aspects of the inventionare described in detail herein and are considered a part of the claimedinvention.

BRIEF DESCRIPTION OF THE DRAWINGS

One or more aspects of the present invention are particularly pointedout and distinctly claimed as examples in the claims at the conclusionof the specification. The foregoing and other objects, features, andadvantages of the invention are apparent from the following detaileddescription taken in conjunction with the accompanying drawings inwhich:

FIG. 1 is a partial cut-away of one embodiment of a tamper-proofelectronic package;

FIG. 2 depicts one embodiment of a tamper-detect sensor with conductivelines forming, at least in part, at least one tamper-detect network, inaccordance with one or more aspects of the present invention;

FIG. 3A is a cross-sectional elevational view of another embodiment of atamper-proof electronic package, or tamper-respondent assembly, whichincludes (in part) an enclosure, and a multilayer circuit board with anembedded tamper-detect sensor, in accordance with one or more aspects ofthe present invention;

FIG. 3B is a top plan view of the multilayer circuit board of FIG. 3A,depicting one embodiment of the secure volume defined, in part, withinthe multilayer circuit board, in accordance with one or more aspects ofthe present invention;

FIG. 4 is a partial cross-sectional elevational view of a more detailedembodiment of the tamper-respondent assembly of FIGS. 3A & 3B comprising(in part) an enclosure and a multilayer circuit board with embeddedtamper-detect sensor, in accordance with one or more aspects of thepresent invention;

FIG. 5 depicts one embodiment of a process of fabricating a multilayercircuit board with an embedded tamper-detect sensor, in accordance withone or more aspects of the present invention;

FIG. 6 is an isometric view of one embodiment of a tamper-respondentassembly, in accordance with one or more aspects of the presentinvention;

FIG. 7A is an inner isometric view of one embodiment of an enclosure ofa tamper-respondent assembly having a tamper-detect sensor disposed overthe inner surface of the enclosure, in accordance with one or moreaspects of the present invention;

FIG. 7B is a partial enlarged depiction of the tamper-respondentassembly of FIG. 7A, taken along line 7B thereof, in accordance with oneor more aspects of the present invention;

FIGS. 8A & 8B depict one embodiment of a process of fabricating atamper-detect sensor over an inner surface of an enclosure of atamper-respondent assembly, in accordance with one or more aspects ofthe present invention;

FIG. 9A is an inner isometric view of the tamper-respondent assembly ofFIG. 7A, with a sensor connection adapter shown coupled to the enclosureand disposed over the tamper-detect sensor, in accordance with one ormore aspects of the present invention;

FIG. 9B is a partial enlarged depiction of the tamper-respondentassembly of FIG. 9A, taken along line 9B thereof, in accordance with oneor more aspects of the present invention;

FIG. 10A depicts an alternate embodiment of a sensor connection adapterof a tamper-respondent assembly, in accordance with one or more aspectsof the present invention; and

FIG. 10B depicts another alternate embodiment of a sensor connectionadapter of a tamper-respondent assembly, in accordance with one or moreaspects of the present invention.

DETAILED DESCRIPTION

Aspects of the present invention and certain features, advantages, anddetails thereof, are explained more fully below with reference to thenon-limiting example(s) illustrated in the accompanying drawings.Descriptions of well-known materials, fabrication tools, processingtechniques, etc., are omitted so as not to unnecessarily obscure theinvention in detail. It should be understood, however, that the detaileddescription and the specific example(s), while indicating aspects of theinvention, are given by way of illustration only, and are not by way oflimitation. Various substitutions, modifications, additions, and/orarrangements, within the spirit and/or scope of the underlying inventiveconcepts will be apparent to those skilled in the art for thisdisclosure. Note further that reference is made below to the drawings,which are not drawn to scale for ease of understanding, wherein the samereference numbers used throughout different figures designate the sameor similar components. Also, note that numerous inventive aspects andfeatures are disclosed herein, and unless otherwise inconsistent, eachdisclosed aspect or feature is combinable with any other disclosedaspect or feature as desired for a particular application, for instance,for establishing a vented, secure volume about an electroniccomponent(s) or electronic assembly to be protected.

Reference is first made to FIG. 1, which illustrates one approach for anelectronic package 100 configured as a tamper-proof electronic packagefor purposes of discussion. In the depicted embodiment, an electronicassembly enclosure 110 is provided containing, for instance, anelectronic assembly, which in one embodiment may include a plurality ofelectronic components, such as an encryption and/or decryption moduleand associated memory. The encryption and/or decryption module maycomprise security-sensitive information with, for instance, access tothe information stored in the module requiring use of a variable key,and with the nature of the key being stored in the associated memorywithin the enclosure.

In one or more implementations, a tamper-proof electronic package ortamper-respondent assembly, such as depicted, is configured or arrangedto detect attempts to tamper with or penetrate into electronic assemblyenclosure 110. Accordingly, electronic assembly enclosure 110 alsoincludes, for instance, a monitor circuit which, if tampering isdetected, activates an erase circuit to erase information stored withinthe associated memory, as well as the encryption and/or decryptionmodule within the communications card. These components may be mountedon, and interconnected by, a multilayer circuit board, such as a printedcircuit board or other multilayer substrate, and be internally orexternally powered via a power supply provided within the electronicassembly enclosure.

In the embodiment illustrated, and as one example only, electronicassembly enclosure 110 may be surrounded by a tamper-detect sensor 120,an encapsulant 130, and an outer, thermally conductive enclosure 140. Inone or more implementations, tamper-detect sensor 120 may include atamper-detection laminate that is folded around electronic assemblyenclosure 110, and encapsulant 130 may be provided in the form of amolding. Tamper-detect sensor 120 may include various detection layers,which are monitored through, for instance, a ribbon cable by theenclosure monitor, against attempts to penetrate enclosure 110 anddamage the enclosure monitor or erase circuit, before information can beerased from the encryption module. The tamper-detect sensor may be, forexample, any such article commercially available or described in variouspublications and issued patents, or any enhanced article such asdisclosed herein.

By way of example, tamper-detect sensor 120 may be formed as atamper-detection laminate comprising a number of separate layers with,for instance, an outermost lamination-detection layer including a matrixof, for example, diagonally-extending or sinusoidally-extending,conductive or semi-conductive lines printed onto a regular, thininsulating film. The matrix of lines forms a number of continuousconductors which would be broken if attempts are made to penetrate thefilm. The lines may be formed, for instance, by printing conductivetraces onto the film and selectively connecting the lines on each side,by conductive vias, near the edges of the film. Connections between thelines and an enclosure monitor of the communications card may beprovided via, for instance, one or more ribbon cables. The ribbon cableitself may be formed of lines of conductive material printed onto anextension of the film, if desired. Connections between the matrix andthe ribbon cable may be made via connectors formed on one edge of thefilm. As noted, the laminate may be wrapped around the electronicassembly enclosure to define the tamper-detect sensor 120 surroundingenclosure 110.

In one or more implementations, the various elements of the laminate maybe adhered together and wrapped around enclosure 110, in a similarmanner to gift-wrapping a parcel, to define the tamper-detect sensorshape 120. The assembly may be placed in a mold which is then filledwith, for instance, cold-pour polyurethane, and the polyurethane may becured and hardened to form an encapsulant 130. The encapsulant may, inone or more embodiments, completely surround the tamper-detect sensor120 and enclosure 110, and thus form a complete environmental seal,protecting the interior of the enclosure. The hardened polyurethane isresilient and increases robustness of the electronic package in normaluse. Outer, thermally conductive enclosure 140 may optionally beprovided over encapsulant 130 to, for instance, provide furtherstructural rigidity to the electronic package.

When considering tamper-proof packaging, the electronic package needs tomaintain defined tamper-proof requirements, such as those set forth inthe National Institutes of Standards and Technology (NIST) PublicationFIPS 140-2, which is a U.S. Government Computer Security Standard, usedto accredit cryptographic modules. The NIST FIPS 140-2 defines fourlevels of security, named Level 1 to Level 4, with Security Level 1providing the lowest level of security, and Security Level 4 providingthe highest level of security. At Security Level 4, physical securitymechanisms are provided to establish a complete envelope of protectionaround the cryptographic module, with the intent of detecting andresponding to any unauthorized attempt at physical access. Penetrationof the cryptographic module enclosure from any direction has a very highprobability of being detected, resulting in the immediate zeroization ofall plain text critical security parameters (CSPs). Security Level 4cryptographic modules are useful for operation in physically unprotectedenvironments. Security Level 4 also protects a cryptographic moduleagainst a security compromise due to environmental conditions orfluctuations outside the module's normal operating ranges for voltageand temperature. Intentional excursions beyond the normal operatingranges may be used by an attacker to thwart the cryptographic module'sdefenses. The cryptographic module is required to either includespecialized environmental protection features designed to detectfluctuations and zeroize, critical security parameters, or to undergorigorous environmental failure testing to provide reasonable assurancesthat the module will not be affected by fluctuations outside the normaloperating range in a manner than can compromise the security of themodule.

To address the demands for ever-improving anti-intrusion technology, andthe higher-performance encryption/decryption functions being provided,enhancements to the tamper-proof, tamper-evident packaging for theelectronic component(s) or assembly at issue are desired.

Numerous enhancements are described herein to, for instance,tamper-proof electronic packages or tamper-respondent assemblies. Asnoted, the numerous inventive aspects described herein may be usedsingly, or in any desired combination. Additionally, in one or moreimplementations, the enhancements described herein may be provided towork within defined space limitations for existing packages.

Disclosed hereinbelow with reference to FIGS. 2-10B are variousapproaches and/or enhancements to creating, for instance, a securevolume for accommodating one or more electronic components, such as oneor more encryption and/or decryption modules and associated componentsof, for instance, a communications card or other electronic assembly tobe protected.

FIG. 2 depicts a portion of one embodiment of a tamper-detection layer205 (or laser and pierce-respondent layer) of a tamper-detect sensor 200or security sensor, such as discussed herein. In FIG. 2,tamper-detection layer 205 includes circuit lines or traces 201 providedon one or both opposite sides of a flexible layer 202, which in one ormore embodiments, may be a flexible insulating layer or film. FIG. 2illustrates circuit lines 201 on, for instance, one side of flexiblelayer 202, with the traces on the opposite side of the film being, forinstance, the same pattern, but (in one or more embodiments) offset tolie directly below spaces 203, between circuit lines 201. As describedbelow, the circuit lines on one side of the flexible layer may be of aline width W_(l) and have a pitch or line-to-line spacing W_(s) suchthat piercing of the layer 205 at any point results in damage to atleast one of the circuit lines traces 201. In one or moreimplementations, the circuit lines may be electrically connectedin-series or parallel to define one or more conductors which may beelectrically connected in a network to an enclosure monitor, which may,in one or more implementations, monitor the resistance of the lines.Detection of an increase, or other change, in resistance, caused bycutting or damaging one of the traces, will cause information within theencryption and/or decryption module to be erased. Providing conductivelines 201 in a pattern, such as a sinusoidal pattern, may advantageouslymake it more difficult to breach tamper-detection layer 205 withoutdetection. Note, in this regard, that conductive lines 201 could beprovided in any desired pattern. For instance, in an alternateimplementation, conductive lines 201 could be provided as parallel,straight conductive lines, if desired, and the pattern or orientation ofthe pattern may vary between sides of a layer, and/or between layers.

As noted, as intrusion technology continues to evolve, anti-intrusiontechnology needs to continue to improve to stay ahead. In one or moreimplementations, the above-summarized tamper-detect sensor 200 of FIG. 2may be disposed over an outer surface of an electronic enclosure, suchas an electronic enclosure described above in connection with FIG. 1.Alternatively, as described further herein, the tamper-detect sensor maycover or line an inner surface of an electronic enclosure to provide asecure volume about at least one electronic component to be protected.Still further, the tamper-detect sensor, or more particularly, thetamper-detect circuit(s) of the sensor, could be embedded within amultilayer circuit board described below.

In one or more aspects, disclosed herein is a tamper-detect sensor 200with circuit lines 201 having reduced line widths W_(l) of, forinstance, 200 μm, or less, such as less than or equal to 100 μm, or evenmore particularly, in the range of 30-70 μm. This is contrasted withconventional trace widths, which are typically on the order of 250 μm orlarger. Commensurate with reducing the circuit line width W_(l),line-to-line spacing width W_(s) 203 is also reduced to less than orequal to 200 μm, such as less than or equal to 100 μm, or for instance,in a range of 30-70 μm. Advantageously, by reducing the line width W_(l)and line-to-line spacing W_(s) of circuit lines 201 within tamper-detectsensor 200, the circuit line width and pitch is on the same order ofmagnitude as the smallest intrusion instruments currently available, andtherefore, any intrusion attempt will necessarily remove a sufficientamount of a circuit line(s) to cause resistance to change, and therebythe tamper intrusion to be detected. Note that, by making the circuitline width of the smaller dimensions disclosed herein, any cutting ordamage to the smaller-dimensioned circuit line will also be more likelyto be detected, that is, due to a greater change in resistance. Forinstance, if an intrusion attempt cuts a 100 μm width line, it is morelikely to reduce the line width sufficiently to detect the intrusion bya change in resistance. A change in a narrower line width is more likelyto result in a detectable change in resistance, compared with, forinstance, a 50% reduction in a more conventional line width of 350 μmto, for instance, 175 μm. The smaller the conductive circuit line widthbecomes, the more likely that a tampering of that line will be detected.

Note also that a variety of materials may advantageously be employed toform the circuit lines when implemented using resistance monitoring. Forinstance, the circuit lines may be formed of a conductive ink (such as acarbon-loaded conductive ink) printed onto one or both opposite sides ofone or more of the flexible layers 202 in a stack of such layers.Alternatively, a metal or metal alloy could be used to form the circuitlines, such as copper, silver, intrinsically conductive polymers, carbonink, or nickel-phosphorus (NiP), such as Omega-Ply®, offered by OmegaTechnologies, Inc. of Culver City, Calif. (USA), or nickel-chrome, suchas Ticer™ offered by Ticer Technologies, Chandler, Ariz. (USA). Notethat the process employed to form the fine circuit lines or traces onthe order described herein is dependent, in part, on the choice ofmaterial used for the circuit lines. For instance, if copper circuitlines are being fabricated, then additive processing, such as plating upcopper traces, or subtractive processing, such as etching away unwantedcopper between trace lines, may be employed. By way of further example,if conductive ink is employed as the circuit line material, fine circuitlines on the order disclosed herein can be achieved by focusing on therheological properties of the conductive ink formulation. Further,rather than simple pneumatics of pushing conductive ink through anaperture in a stencil with a squeegee, the screen emulsion may becharacterized as very thin (for instance, 150 to 200 μm), and a squeegeeangle may be used such that the ink is sheared to achieve conductive inkbreakaway rather than pumping the conductive ink through the screenapertures. Note that the screen for fine line width printing such asdescribed herein may have the following characteristics in one specificembodiment: a fine polyester thread for both warp and weave on the orderof 75 micrometers; a thread count between 250-320 threads per inch; amesh thickness of, for instance, 150 micrometers; an open area betweenthreads that is at least 1.5× to 2.0× the conductive ink particle size;and to maintain dimensional stability of the print, the screen snap-offis kept to a minimum due the screen strain during squeegee passage.

In a further aspect, the flexible layer 202 itself may be furtherreduced in thickness from a typical polyester layer by selecting acrystalline polymer to form the flexible layer or substrate. By way ofexample, the crystalline polymer could comprise polyvinylidenedifluoride (PVDF), or Kapton, or other crystalline polymer material.Advantageously, use of a crystalline polymer as the substrate film mayreduce thickness of the flexible layer 202 to, for instance, 2 milsthick from a more conventional amorphous polyester layer of, forinstance, 5-6 mils. A crystalline polymer can be made much thinner,while still maintaining structural integrity of the flexible substrate,which advantageously allows for far more folding, and greaterreliability of the sensor after folding. Note that the radius of anyfold or curvature of the sensor is necessarily constrained by thethickness of the layers comprising the sensor. Thus, by reducing theflexible layer thickness to, for instance, 2 mils, then in a fourtamper-detection layer stack, the stack thickness can be reduced from,for instance, 20 mils in the case of a typical polyester film, to 10mils or less with the use of crystalline polymer films.

FIGS. 3A & 3B depict one embodiment of a tamper-proof electronic package300, or tamper-respondent assembly, which comprises one or moreelectronic components, such as a circuit 315 and/or electronic devices(or elements) 302 to be protected, in accordance with one or morefurther aspects of the present invention.

Referring collectively to FIGS. 3A & 3B, circuit 315 resides on or isembedded within a multilayer circuit board 310, which also has anembedded tamper-detect sensor 311 that facilitates defining, in part, asecure volume 301 associated with multilayer circuit board 310 that (inone or more embodiments) extends into multilayer circuit board 310. Inparticular, in the embodiment of FIGS. 3A & 3B, secure volume 301 mayexist partially within multilayer circuit board 310, and partially abovemultilayer circuit board 310. One or more electronic devices 302 aremounted to multilayer circuit board 310 within secure volume 301 and maycomprise, for instance, one or more encryption modules and/or decryptionmodules, and/or associated components, to be protected within thetamper-proof electronic package. In one or more implementations, the oneor more electronic components to be protected may comprise, forinstance, a secure communications card of a computer system.

Tamper-proof electronic package 300 further includes an enclosure 320,such as a pedestal-type enclosure, mounted to multilayer circuit board310 within, for instance, a continuous groove (or trench) 312 formedwithin an upper surface of multilayer circuit board 310, and secured tothe multilayer circuit board 310 via, for instance, a structuraladhesive disposed within continuous groove 312. In one or moreembodiments, enclosure 320 may comprise a thermally conductive materialand operate as a heat sink for facilitating cooling of the one or moreelectronic components 302 within the secure volume. A security mesh ortamper-detect sensor 321 may be associated with enclosure 320, forexample, wrapping around the inner surface of enclosure 320, tofacilitate defining, in combination with tamper-detect sensor 311embedded within multilayer circuit board 310, secure volume 301. In oneor more implementations, tamper-detect sensor 321 may extend down intocontinuous groove 312 in multilayer circuit board 310 and may, forinstance, even wrap partially or fully around the lower edge ofenclosure 320 within continuous groove 312 to provide enhanced tamperdetection where enclosure 320 couples to multilayer circuit board 310.In one or more implementations, enclosure 320 may be securely affixed tomultilayer circuit board 310 using, for instance, a bonding materialsuch as an epoxy or other adhesive.

Briefly described, tamper-detect sensor 321 may comprise, in one or moreexamples, one or more tamper-detection layers which include circuitlines or traces provided on one or both sides of a flexible layer, whichin one or more implementations, may be a flexible insulating layer orfilm. The circuit lines on one or both sides of the flexible layer maybe of a line width and have a pitch or line-to-line spacing such thatpiercing of the layer at any point results in damage to one or more ofthe circuit lines or traces. In one or more implementations, the circuitlines may define one or more conductors which may be electricallyconnected in a network to an enclosure monitor or detector 303, whichmonitors, for instance, resistance on the lines, or as described below,in the case of conductors, may monitor for a nonlinearity, or non-linearconductivity change, on the conductive lines. Detection of a change inresistance or a nonlinearity caused by cutting or damaging one or moreof the lines, will cause information within the secure volume to beautomatically erased. The conductive lines of the tamper-detect sensormay be in any desired pattern, such as a sinusoidal pattern, to make itmore difficult to breach the tamper-detection layer without detection.

For resistive monitoring, a variety of materials may be employed to formthe circuit lines. For instance, the circuit lines may be formed of ametal or metal alloy, such as copper, or silver, or could be formed, forexample, of an intrinsically-conductive polymer, carbon ink, or nickelphosphorous (NiP), or Omega-Ply®, offered by Omega Technologies, Inc.,of Culver City, Calif. (USA), or Ticer™, offered by Ticer Technologies,Chandler, Ariz. (USA). The process employed to form the fine circuitlines or traces is dependent, in part, on the choice of materials usedfor the circuit lines. For instance, if copper circuit lines arefabricated, then additive processing, such as plating of copper traces,or subtractive processing, such as etching away unwanted copper betweentrace lines, may be employed.

As noted, in one or more implementations, the circuit lines of thetamper-detect sensor(s) lining the inner surface(s) of enclosure 320, oreven printed directly onto one or more layers formed over the innersurface of enclosure 320, may be connected to define one or more detectnetworks.

If a flexible layer is used over the inner surface of enclosure 320,then the flexible layer may be formed of a crystalline polymer material.For instance, the crystalline polymer could comprise polyvinylidenedifluoride (PVDF), or Kapton, or other crystalline polymer material.Advantageously, a crystalline polymer may be made much thinner, whilestill maintaining structural integrity of the flexible substrate, whichalso allows for enhanced folding, and greater reliability of the sensorafter folding.

As depicted in FIG. 3B, one or more external circuit connection vias 313may be provided within multilayer circuit board 310 for electricallyconnecting to the one or more electronic components within secure volume301. These one or more external circuit connection vias 313 mayelectrically connect to one or more external signal lines or planes (notshown) embedded within multilayer circuit board 310 and extending, forinstance, into a secure base region of (or below) secure volume 301, asexplained further below. Electrical connections to and from securevolume 301 may be provided by coupling to such external signal lines orplanes within the multilayer circuit board 310.

As noted, secure volume 301 may be sized to house one or more electroniccomponents to be protected, and may be constructed to extend intomultilayer circuit board 310. In one or more implementations, multilayercircuit board 310 includes electrical interconnect within the securevolume 301 defined in the board, for instance, for electricallyconnecting one or more tamper-detection layers of the embeddedtamper-detect sensor 311 to associated monitor circuitry also disposedwithin secure volume 301, along with, for instance, one or more daughtercards, such as memory DIMMs, PCIe cards, processor cards, etc.

Note that the packaging embodiment depicted in FIGS. 3A & 3B ispresented by way of example only. Other configurations of enclosure 320,or multilayer circuit board 310 may be employed, and/or other approachesto coupling enclosure 320 and multilayer circuit board 310 may be used.For instance, in one or more alternate implementations, enclosure 320may be securely affixed to an upper surface of multilayer circuit board310 (without a continuous groove) using, for instance, a structuralbonding material such as an epoxy or other adhesive.

By way of further example, FIG. 4 depicts a partial cross-sectionalelevational view of a more detailed embodiment of tamper-proofelectronic package 300, and in particular, of multilayer circuit board310, to which enclosure 320 is secured. In this configuration, theembedded tamper-detect sensor includes multiple tamper-detection layersincluding, by way of example, at least one tamper-detection mat (orbase) layer 400, and at least one tamper-detection frame 401. In theexample depicted, two tamper-detection mat layers 400 and twotamper-detection frames 401 are illustrated, by way of example only. Thelower-most tamper-detection mat layer 400 may be a continuous sense ordetect layer extending completely below the secure volume being definedwithin and/or above multilayer circuit board 310. One or bothtamper-detection mat layers 400 below secure volume 301 may bepartitioned into multiple circuit zones. Within each tamper-detectionmat layer, or more particularly, within each circuit zone of eachtamper-detection mat layer, multiple circuits or conductive traces maybe provided in any desired configuration. Further, the conductive traceswithin the tamper-detection layers may be implemented as, for instance,a resistive layer.

As illustrated, one or more external signal lines or planes 405 mayenter secure volume 301 between, in one embodiment, two tamper-detectionmat layers 400, and then electrically connect upwards into the securevolume 301 through one or more conductive vias, arranged in any desiredlocation and pattern. In the configuration depicted, the one or moretamper-detection frames 401 are disposed at least inside of the areadefined by continuous groove 312 accommodating the base of enclosure320. Together with the tamper-detect sensor(s) 321 associated withenclosure 320, tamper-detection frames 401, and tamper-detection matlayers 400, define secure volume 301, which may extend, in part, intomultilayer circuit board 310. With secure volume 301 defined, in part,within multilayer circuit board 310, the external signal line(s) 405 maybe securely electrically connected to, for instance, the one or moreelectronic components mounted to, or of, multilayer circuit board 310within secure volume 301. In addition, secure volume 301 may accommodateelectrical interconnection of the conductive traces of the multipletamper-detection layers 400, 401, for instance, via appropriate monitorcircuitry.

Added security may be provided by extending tamper-detection mat layers400 (and if desired, tamper-detection frames 401) outward past theperiphery of enclosure 320. In this manner, a line of attack may be mademore difficult at the interface between enclosure 320 and multilayercircuit board 310 since the attack would need to clear, for instance,tamper-detection mat layers 400, the enclosure 320, as well as thetamper-detection frames 401 of the embedded tamper-detect sensor.

Numerous variations on multilayer circuit board 310 of FIGS. 3A-4 arepossible. For instance, in one embodiment, the embedded tamper-detectsensor may include one or more tamper-detection mat layers 400 and oneor more tamper-detection frames 401, such as described above, and atri-plate structure comprising one or more external signal lines orlayers sandwiched between an upper ground plane and a lower groundplane. In this configuration, high-speed transfer of signals to and fromthe secure volume, and in particular, to and from the one or moreelectronic components resident within the secure volume, would befacilitated.

Note also that, once the secure volume is defined in part withinmultilayer circuit board 310, conductive vias within the secure volumebetween layers of multilayer circuit board 310 may be either aligned, oroffset, as desired, dependent upon the implementation. Alignment ofconductive vias may facilitate, for instance, providing a shortestconnection path, while offsetting conductive vias between layers mayfurther enhance security of the tamper-proof electronic package bymaking an attack into the secure volume through or around one or moretamper-detection layers of the multiple tamper-detection layers moredifficult.

The tamper-detection layers of the embedded tamper-detect sensor formedwithin the multilayer circuit board of the electronic circuit orelectronic package may include multiple conductive traces or linesformed between, for instance, respective sets of input and outputcontacts or vias at the trace termination points. Any pattern and anynumber of conductive traces or circuits may be employed in defining atamper-detection layer or a tamper-detection circuit zone within atamper-detection layer. For instance, 4, 6, 8, etc., conductive tracesmay be formed in parallel (or otherwise) within a given tamper-detectionlayer or circuit zone between the respective sets of input and outputcontacts to those conductive traces.

In one or more implementations, the multilayer circuit board may be amultilayer wiring board or printed circuit board formed, for instance,by building up the multiple layers of the board. FIG. 5 illustrates oneembodiment for forming and patterning a tamper-detection layer withinsuch a multilayer circuit board.

As illustrated in FIG. 5, in one or more implementations, atamper-detection layer, such as a tamper-detection mat layer or atamper-detection frame disclosed herein, may be formed by providing amaterial stack comprising, at least in part, a structural layer 501,such as a pre-preg (or pre-impregnated) material layer, a trace materiallayer 502 for use in defining the desired trace patterns, and anoverlying conductive material layer 503, to be patterned to defineconductive contacts or vias electrically connecting to the pattern oftraces being formed within the trace material layer 502, for instance,at trace terminal points. In one or more implementations, the tracematerial layer 502 may comprise nickel phosphorous (NiP), and theoverlying conductive layer 503 may comprise copper. Note that thesematerials are identified by way of example only, and that other traceand/or conductive materials may be used within the build-up 500.

A first photoresist 504 is provided over build-up 500, and patternedwith one or more openings 505, through which the overlying conductivelayer 503 may be etched. Depending on the materials employed, and theetch processes used, a second etch process may be desired to removeportions of trace material layer 502 to define the conductive traces ofthe subject tamper-detection layer. First photoresist 504 may then beremoved, and a second photoresist 504′ is provided over the conductivelayer 503 features to remain, such as the input and output contacts.Exposed portions of conductive layer 503 are then etched, and the secondphotoresist 504′ may be removed, with any opening in the layer beingfilled, for instance, with an adhesive (or pre-preg) 506 and a nextbuild-up layer is provided, as shown. Note that in this implementation,most of overlying conductive layer 503 is etched away, with only theconductive contacts or vias remaining where desired, for instance, atthe terminal points of the traces formed within the layer by thepatterning of the trace material layer 502. Note that any of a varietyof materials may be employed to form the conductive lines or traceswithin a tamper-detection layer. Nickel-phosphorous (NiP) isparticularly advantageous as a material since it is resistant to contactby solder, or use of a conductive adhesive to bond to it, making itharder to bridge from one circuit or trace to the next during an attemptto penetrate into the protected secure volume of the electronic circuit.Other materials which could be employed include OhmegaPly®, offered byOhmega Technologies, Inc., of Culver City, Calif. (USA), or Ticer™,offered by Ticer Technologies of Chandler, Ariz. (USA).

The trace lines or circuits within the tamper-detection layers, and inparticular, the tamper-detection circuit zones, of the embeddedtamper-detect sensor, along with the tamper detector monitoring theenclosure, may be electrically connected to detect or compare circuitryprovided, for instance, within secure volume 301 (FIG. 3A) of thetamper-proof electronic package. The detect circuitry may includevarious bridges or compare circuits, and conventional printed wiringboard electrical interconnect inside secure volume 301 (FIG. 3A), forinstance, located within the secure volume defined by thetamper-detection frames 401 (FIG. 4), and the tamper-detection matlayers 400 (FIG. 4).

Note that advantageously, different tamper-detection circuit zones ondifferent tamper-detection layers may be electrically interconnectedinto, for instance, the same detect circuitry. Thus, any of a largenumber of interconnect configurations may be possible. For instance, ifeach of two tamper-detection mat layers contains 30 tamper-detectioncircuit zones, and each of two tamper-detection frames contains 4tamper-detection circuit zones, then, for instance, the resultant 68tamper-detection circuit zones may be connected in any configurationwithin the secure volume to create the desired arrangement of circuitnetworks within the secure volume being monitored for changes inresistance or tampering. Note in this regard, that the power supply orbattery for the tamper-detect sensor may be located internal or externalto the secure volume, with the sensor being configured to trip anddestroy any protected or critical data if the power supply or battery istampered with.

By way of further example, an isometric view of one embodiment of atamper-proof electronic package 300 is depicted in FIG. 6, wherein anenclosure 320 is shown sealed to multilayer circuit board 310 to definea secure volume about one or more electronic components, as describedherein. In the embodiment depicted, enclosure 320 may be formed of athermally conductive material, and includes a main surface 601 andsidewall(s) 602 which include sidewall corners 603. An inner surface ofenclosure 320 would include an inner main surface, and an inner sidewallsurface corresponding to main surface 601 and sidewall(s) 602respectively, with the inner main surface and inner sidewall surfacesbeing covered, at least in part, by one or more tamper-detect sensors,such as described above. A power supply 605 or battery for thetamper-detect sensor may be located, as depicted in this embodiment,external to the secure volume, with the tamper detector being configuredto trip and destroy any protected or critical data if the power supplyor battery is tampered with. Enclosure 320 may be adhered ormechanically affixed to multilayer circuit board 310, which as notedabove, may include its own embedded tamper-detect sensor(s).

By way of further enhancement, disclosed herein are additionaltamper-respondent assemblies with sensor connection adapters tofacilitate electrically connecting a monitor circuit or device to thesensor lines of a tamper-detect sensor, and in particular, to the sensorlines of a tamper-detect sensor disposed over (such as, formed over) aninner surface of an enclosure. More particularly, the sensor connectionadapters disclosed herein facilitate electrical connection between themonitor and tamper-detect sensor, as well as complement thetamper-detect capability of the assembly. For instance, the sensorconnection adapter presented herein is, in one or more embodiments, afragile interposer which breaks or separates from the enclosure with anattempted tampering of the assembly at or near the interposer, therebyensuring breaking of electrical connection between the monitor and thetamper-respondent sensor, and triggering detection of the tamper event.

In general, described hereinbelow are tamper-respondent assemblies andmethods of fabrication, which further incorporate a sensor connectionadapter with characteristics that facilitate tamper detection within thetamper-respondent assembly responsive to a tamper event, andparticularly, a tamper event contacting, or applying force to the sensorconnection adapter. In one or more implementations, thetamper-respondent assembly includes an enclosure, a tamper-detectsensor, a monitor, and a sensor connection adapter. The enclosure is toenclose, at least in part, at least one electronic component to beprotected, and the tamper-detect sensor is disposed over an innersurface of the enclosure to facilitate defining a secure volume aboutthe at least one electronic component. The tamper-detect sensor includessensor lines disposed over the inner surface of the enclosure. Themonitor (or monitor circuitry) may be disposed within the secure volume,and monitors the tamper-detect sensor for a tamper event. The sensorconnection adapter is coupled to the inner surface of the enclosure, andis disposed over a portion of the tamper-detect sensor within the securevolume. As noted, the sensor connection adapter facilitates electricallyconnecting the monitor to the sensor lines of the tamper-detect sensor.

As discussed further below, the tamper-detect sensor may be a sensorsuch as described above in connection with FIGS. 2-3B, or alternatively,may include sensor lines formed in one or more layers disposed directlyon the inner surface of the enclosure. Also, note that the monitor mayrefer to any monitor circuitry monitoring the tamper-detect sensor for atamper event, such as the enclosure monitor or detector 303 referencedabove in connection with FIG. 3A. In addition, note that althoughreferred to herein as a sensor connection adapter, that more than onesensor connection adapter may be employed in a particularimplementation, if desired.

In one or more embodiments, the sensor connection adapter is aninterposer which includes a carrier or substrate with circuit lines, andthe carrier resides over a portion of the sensor lines of thetamper-detect sensor. For instance, the carrier may be a friable glass,ceramic, molded plastic carrier, etc., which is relatively weaklyadhesively coupled at N discrete points to the inner surface of theenclosure via, for instance, a thermoset material selected or engineeredto provide a desired breaking interface of the carrier to the enclosure.In this manner, any tamper event resulting in force being appliedagainst the carrier may readily dislodge the carrier from the innersurface of the enclosure, and in doing so, break one or more of theconnectors electrically connecting the sensor connection adapter to thesensor lines of the tamper-detect sensor.

By way of example, in one or more embodiments, the sensor connectionadapter includes one or more first connectors which electrically connectthe circuit lines of the sensor connection adapter to the sensor linesof the tamper-detect sensor. For instance, the first connector(s) may bean electrical connector type selected from the group consisting of awire-bond connector, a solder-ball connector, a spring connector, and azebra-strip connector. Those skilled in the art will recognize, however,that other connector types may alternatively be employed, provided theyresult in breaking of electrical contact between the sensor connectionadapter and the sensor lines of the tamper-detect sensor should, forexample, a tamper event result in dislodging of the carrier from theinner surface of the enclosure.

In one or more implementations, the sensor lines of the tamper-detectsensor may have a common line width, and the first connector(s) may havea different (for instance, smaller) width or diameter than the linewidth of the sensor lines.

In one or more embodiments, the sensor connection adapter mayelectrically connect to the monitor via, at least in part, one or moresecond connectors. The second connector(s) may be a different connectortype than the first connector(s). By way of example, the secondconnector(s) may be a ribbon cable connector which electrically couplesthe adapter to the monitor within the secure volume.

In one or more embodiments, the sensor connection adapter electricallyconnects to the sensor lines of the tamper-detect sensor via a first setof connectors, and electrically connects to the monitor via, at least inpart, a second set of connectors, where the first set of connectorsincludes a larger number of discrete connectors than the second set ofconnectors. For instance, in one or more implementations, the circuitlines on the sensor connection adapter may include one or more aspectsof the monitor circuitry, such as, for instance, a Wheatstone bridge orother circuitry, which may result in a smaller number of connectorsrequired at the second set of connectors than the first set ofconnectors.

As described above, in one or more embodiments, the tamper-respondentassembly may also include a multilayer circuit board with an embeddedtamper-detect sensor. The tamper-detect sensor disposed over the innersurface of the enclosure, and the embedded tamper-detect sensor withinthe multilayer circuit board, together facilitate defining the securevolume within which the electronic component(s) resides.

FIGS. 7A & 7B depicts another embodiment of an enclosure 320′ for atamper-proof electronic package, such as described above in connectionwith FIGS. 2-6. Enclosure 320′ facilitates, in one or more embodiments,establishing a secure volume about one or more electronic components tobe protected by mounting to, for instance, a multilayer circuit board,such as the multilayer circuit board described above (which as noted,may include one or more embedded tamper-detect sensor(s)). Asillustrated, enclosure 320′ includes an inner surface 705, such as thedepicted inner main surface and inner sidewall surfaces, which areprocessed (in one or more embodiments) to include sensor lines 701 of atamper-detect sensor 700 formed in one or more layers deposited onto theinner surface 705 of enclosure 320′. In the illustrated embodiment,sensor line ends 702 (FIG. 7B) are depicted, to which electrical contactis to be made to facilitate connection to a monitor circuit providing,for instance, a DC signal to the sensor lines to monitor the lines for atamper event. Note that a variety of approaches may be employed toestablish sensor lines 701 directly on inner surface 705 of enclosure320′. For instance, in one or more embodiments, enclosure 320′ may beformed of a thermally conductive material, and a dielectric layer may bedisposed over inner surface 705, with the sensor lines 701 being formedover, or in part, within, the dielectric layer. One embodiment of such afabrication process is depicted in FIGS. 8A & 8B.

Referring to FIGS. 8A & 8B, a dielectric layer 800 of, for instance, apolyurethane material, may be provided over inner surface 705 ofenclosure 320′. In one or more embodiments, laser-direct structuring(LDS) may be used in forming one or more openings 801, which expose seedmaterial 802, such as metal seeds provided within dielectric layer 800.The structure of FIG. 8A may then be, for instance, immersed in achemical bath to grow sensor lines 803 from seed material 802. By way ofspecific example, the sensor lines grown might be copper lines or nickelphosphorous lines. Note that using the process of FIGS. 8A & 8B, sensorlines of any desired configuration may be produced, including sensorlines with thicknesses and spacing such as described above, forinstance, in connection with FIG. 2. Note also that the fabricationprocess of FIGS. 8A & 8B is provided by way of example only, and not byway of limitation with respect to the disclosure and claims providedherein. The sensor connection adapter disclosed may be used incombination with an enclosure having any of a variety of tamper-detectsensors formed or disposed over the inner surface of the enclosure in avariety of manners.

FIGS. 9A & 9B depict the partial tamper-respondent assembly of FIGS. 7A& 7B, with a sensor connection adapter 900 coupled to the inner surfaceof enclosure 320′, such as over sensor lines 701 of tamper-detect sensor700. In one or more embodiments, sensor connection adapter 900facilitates electrical connection between the monitor of thetamper-respondent assembly and the sensor lines of the tamper-detectsensor. As noted, the monitor may be, by way of example, disposed withinthe secure volume defined by the tamper-respondent assembly, such as onthe multilayer circuit board to which enclosure 320′ is to be secured.In the embodiment illustrated, sensor connection adapter 900 includes acarrier 901, with circuit lines 902 disposed on (or within) carrier 901.In one example, carrier 901 may be a thin, rigid substrate or plateformed of, for instance, glass, ceramic, molded plate, etc., and circuitlines 902 may be formed of any conductive material.

In the illustrated embodiment, sensor connection adapter 900electrically connects to sensor line ends 702 of sensor lines 701 viaone or more first connectors 910, and electrically connects to themonitor (not shown) via, at least in part, one or more second connectors920. Note that as used herein, the first and second connectors may referto first and second electrical connections, and may be provided asdifferent connector or connection types. For instance, the firstconnector(s) 910 may each be a connector type such as a wire-bondconnector, a solder-ball connector, a spring connector, a zebra-stripconnector, etc., and the second connector(s) may be, or be part of, aribbon cable connector, such as illustrated in FIG. 9A. Inimplementation, sensor connection adapter 900 advantageously adapts theline width and/or pitch of sensor lines 701 to the line width and/orpitch of the second connector(s) 920.

As noted, second connector 920 may electrically connect to a monitor ortamper detector disposed within the secure volume of thetamper-respondent assembly, such as mounted to an upper surface of themultilayer circuit board to which enclosure 320′ may be secured. Asillustrated, in one or more embodiments, first connector(s) 910 andsecond connector(s) 920 may be different connector types. In addition,note that sensor connection adapter 900 may include, for instance, themonitor circuitry or a portion of the monitor circuitry employed inmonitoring sensor lines 701 of tamper-detect sensor 700. For instance,sensor connection adapter 900 may include one or more Wheatstone bridgeselectrically connected between first connector(s) 910 and secondconnector(s) 920. In such embodiments, the number of first connectors910 may be larger than the number of second connectors (or secondconnector lines) 920 connected to sensor connection adapter 900. Asnoted above, should the monitor detect a tamper event, then the monitormay signal one or more electronic components within the secure volume todestroy any protected or critical data, based on detection of the tamperevent.

Advantageously, in one or more implementations, the first connectors 910may have a different line width, such as a smaller line width, than theline width of the sensor lines 701, and thus, the first connectors mayelectrically connect to the ends 902 of the respective sensor lines, oreven intermediate the ends of the sensor lines (if, for instance, it isdesired to establish a voltage divider). In one or more implementations,copper, nickel, or gold wire-bonds may be employed as the firstconnectors 910.

In one or more embodiments, the first connectors 910 may be chosen withthe goal of breaking should a tamper event dislodge sensor connectionadapter 900 from the enclosure 320′. By way of example, carrier 901 maybe adhesively coupled at N discrete points to the inner surface of theenclosure 320′ via a thermoset material. For instance, three discretepoints of thermoset material may be provided, with the material beingdisposed between sensor lines 701, over which carrier 901 resides. If anattempted tamper event applies force to the carrier, or even to the mainsurface of enclosure 320′ (in this example), the force (if sufficientlysignificant) will dislodge carrier 901, and in doing so, break one ormore of the first connectors 910, such that the tamper event may bedetected.

Numerous enhancements to the tamper-respondent assembly may be made tofacilitate, for instance, breaking of one or more of first connectors910, second connectors 920, or carrier 901, responsive to an attemptedtamper event applying force to the carrier. For instance, sensor lines(not shown) could be provided on the opposite main surface of carrier901 to the main surface having circuit lines 902. These sensor linescould be similar to sensor lines 701 of tamper-detect sensor 700, andmay comprise, for instance, one or more layers deposited onto thesurface of carrier 901 in opposing relation to the inner surface ofenclosure 320′. These sensor lines would be electrically connected toform part of a tamper-detect sensor associated with carrier 901. In sucha case, should an attempted tamper event penetrate enclosure 320′ andtamper-detect sensor 700, it would also need to perforate carrier 901itself if attempted in the region of the carrier. This could involveapplying force and/or vibration, or increased temperature, such as withthe use of a laser, which would amplify the possibility of disruption ofthe carrier mounting, and/or the sensor lines on the opposite mainsurface of carrier 901 in opposing relation to enclosure 320′,triggering detection of the tamper event.

As a further enhancement, sensor lines 701 of tamper-detect sensor 700may be formed so as to be brittle. In such a case, an attempted tamperevent involving drilling through enclosure 320′ would apply tensile orshear strain to the mount scheme of the carrier (such as a thermosetresin anchoring the carrier to the cover surface, or otherplastic/solder material), which may become dislodged from its positionby breaking, and in doing so, breaking one or more of the adjacent,brittle sensor lines 701 of tamper-detect sensor 700, irrespective ofwhether dislodging of carrier 901 also breaks one or more of firstconnectors 910, or of second connectors 920. Affecting desiredmechanical properties of the interface between the carrier anchoringmaterial, and the base material (e.g., polyurethane layer affixed toenclosure 320′) or the inscribed sensor lines 701, is a matter ofselection of, for instance, a polymer with the desired, specificadhesion properties, either to the polyurethane, or any other resinselected as base material supporting the sensor lines 701. The adhesivestrength of the different interfaces can be engineered accordingly to aselected, or desired, breaking interface.

By way of further enhancement, carrier 901 may be engineered to befragile, being designed to fracture when an external force or load isapplied, thus breaking one or more of the electrical interconnectionsprovided by sensor connection adapter 900. By way of example, a fragilecarrier may be a pre-engineered carrier, such as a thin glass, quartz,silicon, ceramic, etc., substrate, designed to break with theapplication of sufficient force or stress. By way of specific example,the carrier could comprise a highly-stressed glass carrier with acompressively-stressed surface layer. For instance, the glass carriercould comprise a machined glass or molded (or cast) glass, stressedusing an ion-exchange process. Note in this regard, that the stressedglass may be any friable glass or friable glass ceramic.

In one or more embodiments, the compressively-stressed surface layer(s)may be compressively-stressed or tailored so that the stressed glassfragments into, for instance, glass particles less than 1000 μm in size,such as in the range of 100-1000 μm in size, with an attempted tamperintrusion event through the stressed glass. The fragmentation size ofthe glass particles may be tailored to ensure that the tamper-respondentdetector monitoring the tamper-detect sensor senses the tamper intrusionevent. By way of example, the tamper-respondent detector could monitorstructural integrity of the stressed glass carrier via a sensorassociated with the stressed glass, and the fragmentation size of theglass particles could be sufficient to, for instance, break the sensor,and thereby signal a tamper event. For instance, one or more sensorscould be associated with the stressed glass carrier, and be sized,designed or configured to fracture with fragmentation of the stressedglass, thereby, for instance, open-circuiting the sensor and allowingmonitor circuitry of or associated with the detector to detect thetamper intrusion event.

FIGS. 10A & 10B depict alternate embodiments of the first connectors forelectrically connecting sensor connection adapter 900 to sensor lines701. As illustrated in FIG. 10A, solder balls 1000 may be employed (inone or more embodiments) to electrically connect sensor lines 701 andcircuit lines 902. Note in this regard that a variety of designs may beemployed, including placing circuit lines 902 on the main surface ofcarrier 901 in contact with solder balls 1000, or through substrate viasmay be provided within the carrier to electrically connect from one mainsurface of carrier 901 to the other main surface.

FIG. 10B depicts the sensor connection adapter 900 of FIGS. 9A & 10A,with the first connectors shown in this example as spring-typeconnectors 1010 electrically connecting sensor lines 701 and to circuitlines 902 of carrier 901. As noted above, other types of connectors mayalso be employed as first connectors. For instance, zebra stripconnectors could be used if desired. A common characteristic of theabove-noted connectors is that they may readily break or open circuitwith dislodging of sensor connection adapter 900 from the enclosure.

Those skilled in the art will note from the description provided hereinthat the adapter is a relatively fragile interposer that may respond toa tamper event at or impacting the adapter by dislodging from theenclosure of the tamper-respondent assembly, and in doing so, break oneor more of the first connector(s), such as the wire-bonds, solder-balls,or spring connections noted above, with the resultant open circuit beingreadily detected by the monitor of the tamper-respondent assembly. Inthis manner, the sensor connection adapter disclosed advantageouslybuilds on the tamper-detect sensing provided by the tamper-detect sensorand monitor circuit by providing a further location or connection thatis sensitive to a tamper event. Note also, in one or more enhancedimplementation, the sensor connection adapter may be implemented withthe monitor logic or circuit disposed on the adapter itself, or aportion of the monitor, as desired.

The terminology used herein is for the purpose of describing particularembodiments only and is not intended to be limiting of the invention. Asused herein, the singular forms “a”, “an” and “the” are intended toinclude the plural forms as well, unless the context clearly indicatesotherwise. It will be further understood that the terms “comprise” (andany form of comprise, such as “comprises” and “comprising”), “have” (andany form of have, such as “has” and “having”), “include” (and any formof include, such as “includes” and “including”), and “contain” (and anyform contain, such as “contains” and “containing”) are open-endedlinking verbs. As a result, a method or device that “comprises”, “has”,“includes” or “contains” one or more steps or elements possesses thoseone or more steps or elements, but is not limited to possessing onlythose one or more steps or elements. Likewise, a step of a method or anelement of a device that “comprises”, “has”, “includes” or “contains”one or more features possesses those one or more features, but is notlimited to possessing only those one or more features. Furthermore, adevice or structure that is configured in a certain way is configured inat least that way, but may also be configured in ways that are notlisted.

The corresponding structures, materials, acts, and equivalents of allmeans or step plus function elements in the claims below, if any, areintended to include any structure, material, or act for performing thefunction in combination with other claimed elements as specificallyclaimed. The description of the present invention has been presented forpurposes of illustration and description, but is not intended to beexhaustive or limited to the invention in the form disclosed. Manymodifications and variations will be apparent to those of ordinary skillin the art without departing from the scope and spirit of the invention.The embodiment was chosen and described in order to best explain theprinciples of one or more aspects of the invention and the practicalapplication, and to enable others of ordinary skill in the art tounderstand one or more aspects of the invention for various embodimentswith various modifications as are suited to the particular usecontemplated.

What is claimed is:
 1. A tamper-respondent assembly comprising: anenclosure to enclose, at least in part, at least one electroniccomponent; a tamper-detect sensor disposed over an inner surface of theenclosure to facilitate defining a secure volume about the at last oneelectronic component, the tamper-detect sensor including sensor linesdisposed over the inner surface of the enclosure; a monitor to monitorthe tamper-detect sensor for a tamper event; and a sensor connectionadapter adhesively coupled at discrete points to the inner surface ofthe enclosure, and disposed over the tamper-detect sensor within thesecure volume, with a portion of the sensor lines of the tamper-detectsensor being disposed between the inner surface of the enclosure and thesensor connection adapter, the sensor connection adapter facilitatingelectrically connecting the monitor to the sensor lines of thetamper-detect sensor, and the sensor connection adapter dislodging fromthe inner surface of the enclosure with an attempted tamper event intothe secure volume through the enclosure and the sensor connectionadapter, the dislodging facilitating detection of the attempted tamperevent by breaking, at least in part, electrical connection of themonitor to the sensor lines of the tamper-detect sensor.
 2. Thetamper-respondent assembly of claim 1, wherein the sensor connectionadapter comprises a carrier with circuit lines, the carrier residingover a portion of the sensor lines of the tamper-detect sensor.
 3. Thetamper-respondent assembly of claim 2, wherein the sensor connectionadapter electrically connects to the sensor lines of the tamper-detectsensor via at least one first connector.
 4. The tamper-respondentassembly of claim 3, wherein the at least one first connector comprisesa connector type selected from the group consisting of a wire-bondconnector, a solder-ball connector, a spring connector, and a zebrastrip connector.
 5. The tamper-respondent assembly of claim 3, whereinthe sensor lines of the tamper-detect sensor have a line width, andwherein the at least one first connector has a different width than theline width of the sensor lines.
 6. The tamper-respondent assembly ofclaim 3, wherein the sensor connection adapter electrically connects tothe monitor via, at least in part, at least one second connector, the atlast one second connector being a different connector type than the atleast one first connector.
 7. The tamper-respondent assembly of claim 6,wherein the at least one second connector comprises a ribbon cableconnector.
 8. The tamper-respondent assembly of claim 2, wherein thesensor connection adapter electrically connects to the sensor lines ofthe tamper-detect sensor via a first set of connectors, and the sensorconnection adapter electrically connects to the monitor via, at least inpart, a second set of connectors, the first set of connectors includinga larger number of connectors than the second of connectors.
 9. Thetamper-respondent assembly of claim 8, wherein the carrier comprises arigid substrate adhesively coupled at N discrete points to the enclosurevia a thermoset material selected to provide a desired breakinginterface of the carrier to the enclosure, and wherein the first set ofconnectors open circuit with dislodging of the carrier from theenclosure.
 10. The tamper-respondent assembly of claim 1, furthercomprising: a multilayer circuit board; and an embedded tamper-detectsensor embedded within the multilayer circuit board, the tamper-detectsensor disposed over the inner surface of the enclosure and the embeddedtamper-detect sensor within the multilayer circuit board togetherfacilitating defining the secure volume within which the at least oneelectronic component resides.
 11. A tamper-respondent assemblycomprising: at least one electronic component; an enclosure enclosing,at least in part, the at least one electronic component; a tamper-detectsensor disposed over an inner surface of the enclosure to facilitatedefining a secure volume about the at least one electronic component,the tamper-detect sensor including sensor lines disposed over the innersurface of the enclosure; a monitor to monitor the tamper-detect sensorfor a tamper event; and a sensor connection adapter adhesively coupledat discrete points to the inner surface of the enclosure, and disposedover the tamper-detect sensor within the secure volume, with a portionof the sensor lines of the tamper-detect sensor being disposed betweenthe inner surface of the enclosure and the sensor connection adapter,the sensor connection adapter facilitating electrically connecting themonitor to the sensor lines of the tamper-detect sensor, and the sensorconnection adapter dislodging from the inner surface of the enclosurewith an attempted tamper event into the secure volume through theenclosure and the sensor connection adapter, the dislodging facilitatingdetection of the attempted tamper event by breaking, at least in part,electrical connection of the monitor to the sensor lines of thetamper-detect sensor.
 12. The tamper-respondent assembly of claim 11,wherein the sensor connection adapter comprises a carrier with circuitlines, the carrier residing over a portion of the sensor lines of thetamper-detect sensor.
 13. The tamper-respondent assembly of claim 12,wherein the sensor connection adapter electrically connects to thesensor lines of the tamper-detect sensor via at least one firstconnector.
 14. The tamper-respondent assembly of claim 13, wherein theat least one first connector comprises a connector type selected fromthe group consisting of a wire-bond connector, a solder-ball connector,a spring connector, and a zebra strip connector.
 15. Thetamper-respondent assembly of claim 13, wherein the sensor lines of thetamper-detect sensor have a line width, and wherein the at least onefirst connector has a different width than the line width of the sensorlines.
 16. The tamper-respondent assembly of claim 13, wherein thesensor connection adapter electrically connects to the monitor via, atleast in part, at least one second connector, the at last one secondconnector being a different connector type than the at least one firstconnector.
 17. The tamper-respondent assembly of claim 12, wherein thesensor connection adapter electrically connects to the sensor lines ofthe tamper-detect sensor via a first set of connectors, and the sensorconnection adapter electrically connects to the monitor via, at least inpart, a second set of connectors, the first set of connectors includinga larger number of connectors than the second of connectors.
 18. Thetamper-respondent assembly of claim 17, wherein the carrier comprises arigid substrate adhesively coupled at N discrete points to the enclosurevia a thermoset material selected to provide a desired breakinginterface of the carrier to the enclosure, and wherein the first set ofconnectors open circuit with dislodging of the carrier from theenclosure.
 19. The tamper-respondent assembly of claim 11, furthercomprising: a multilayer circuit board; and an embedded tamper-detectsensor embedded within the multilayer circuit board, the tamper-detectsensor disposed over the inner surface of the enclosure and the embeddedtamper-detect sensor within the multilayer circuit board togetherfacilitating defining the secure volume within which the at least oneelectronic component resides.
 20. A fabrication method comprising:fabricating a tamper-respondent assembly, the fabricating comprising:providing an enclosure to enclosure, at least in part, at least oneelectronic component to be protected; providing a tamper-detect sensordisposed over an inner surface of the enclosure to facilitate defining asecure volume about the at least one electronic component, thetamper-detect sensor including sensor lines disposed over the innersurface of the enclosure; providing a monitor to monitor thetamper-detect sensor for a tamper event; and providing a sensorconnection adapter, and adhesively coupling at discrete points thesensor connection adapter to the inner surface of the enclosure, overthe tamper-detect sensor, with a portion of the sensor lines of thetamper-detect sensor being disposed between the inner surface of theenclosure and the sensor connection adapter, the sensor connectionadapter being disposed within the secure volume and facilitatingelectrically connecting the monitor to the sensor lines of thetamper-detect sensor, and the sensor connection adapter dislodging fromthe inner surface of the enclosure with an attempted tamper event intothe secure volume through the enclosure and the sensor connectionadapter, the dislodging facilitating detection of the attempted tamperevent by breaking, at least in part, electrical connection of themonitor to the sensor lines of the tamper-detect sensor.